I kusy moved the elasticsearch indexes to separate partition to prevenf them filling up roit partition.
So i have small graylog server partition and large partition for elasticsearch.
If i was going to mount / var pn a separate partition, i would do it in os setup, there is an option for it in ubuntu from memory